After upgrading to Data Loss Prevention (DLP) 16.x, administrators notice that Audit Log entries for Discover Target – modify events show a blank entry for the Scan Schedule field, even when a schedule is actively configured for the target.
Product: Data Loss Prevention (DLP) Enforce
Version: 16.0, 16.1, and higher
Feature: Audit Logging, Network Discover
This is an architectural design behavior within the Enforce console's auditing framework. The Audit Log schema supports the "Scan Schedule" attribute, but it is specifically integrated only with the Discover 2G (High Speed Discovery) architecture.
Legacy Network Discover (1G) scan types—including single-server and grid scans—do not support the transmission of schedule metadata to the audit logging service. As a result:
Discover 2G Targets: The Audit Log correctly displays the modified scan schedule.
Discover 1G/Grid Targets: The Audit Log captures the modification event but leaves the scan schedule detail blank.
No action is required as the system is operating as designed. The blank entry for legacy 1G targets indicates the modification occurred but confirms that schedule metadata is not supported for logging on that specific scan type
If detailed auditing of scan schedules is required, consider migrating compatible File System targets to the High Speed Discovery (2G) engine.